See it liveHow it worksPacksQuestionnairesTrustYour recordPricingFree toolsBlogSign inStart free
All posts

How to write a sub-processor list (template, and what customers check)

4 September 20267 min read

Of all the documents a customer asks a supplier for, the sub-processor list is the one they read most carefully, because it is the one they can check. Every entry names a company they can look up, a country they have a view on, and a claim about a contract they can ask you to produce. It is also the document most small suppliers get wrong, usually by naming tools instead of companies.

This is how to write one that survives a reviewer, with a template you can copy and twelve entries you probably need.

What a sub-processor is, and what it is not

If you process personal data on a customer's behalf (you are their processor), then any third party you use that also touches that data is a sub-processor. Your hosting provider, your email service, your CRM, your payment processor, your AI API. Under Article 28(2) GDPR you need the customer's prior authorisation for them, general or specific, and under 28(4) you are liable to the customer for what they do.

Not sub-processors: tools that handle only your own data (your accountant, your payroll provider, for the customer's purposes), and independent controllers you disclose data to on their own account. The line is whether the third party processes the customer's personal data on your instructions. Analytics on your marketing site is your business as a controller; analytics inside the product you run for the customer is a sub-processor.

The columns

Twelve entries most small suppliers need

Entities and transfer mechanisms as recorded in Rowpa's vendor library on 4 September 2026; regions are the ones commonly configured. Check your own account settings and each vendor's current DPA before you publish.

ToolLegal entityPurposeHostingAgreement and transfer
SupabaseSupabase Inc. (US)Database and authEU, Frankfurt (region you choose)DPA accepted in dashboard; SCCs
VercelVercel, Inc. (US)Application hostingGlobal edge, EU region configurableDPA in terms; DPF with UK Extension
StripeStripe, Inc. (US)PaymentsEU and USDPA in terms; SCCs and DPF
MailchimpIntuit Inc. (US)Email marketingUSDPA in terms; SCCs and DPF
ResendResend Inc. (US)Transactional emailUS, EU region availableDPA in terms; SCCs
HubSpotHubSpot, Inc. (US)CRMUS, EU data centre availableDPA in terms; SCCs and DPF
Google WorkspaceGoogle LLC (US)Email, documentsGlobal, EU data regions availableDPA in terms; SCCs and DPF
Microsoft 365Microsoft Corporation (US)Email, documentsEU Data Boundary availableDPA in terms; SCCs and DPF with UK Extension
XeroXero Limited (NZ)AccountingAWS, region per accountDPA in terms; SCCs (NZ also holds adequacy)
AnthropicAnthropic, PBC (US)AI drafting (API)Confirm account processing locationsVerify executed DPA and applicable transfer safeguards
OpenAIOpenAI, Inc. (US)AI features (API)Confirm account processing locationsVerify executed DPA and applicable transfer safeguards
CloudflareCloudflare, Inc. (US)CDN and DNSGlobal edgeDPA in terms; SCCs and DPF

Publishing it, and notifying changes

Most customer DPAs grant general authorisation on condition that you keep a current list somewhere they can see it and tell them before you add a sub-processor, with a window (often 30 days) to object. So the list needs a home with a date on it, and a way to notify. The usual shape is a public page with the current list, a version history, and an email to customers who have asked to be told. Big vendors run this at scale (Microsoft, OpenAI and AWS all publish theirs); for a small supplier the same three things fit on one page.

The three mistakes reviewers catch

A template

Sub-processors of [Your Company Ltd], version [n], [date]
We use the following sub-processors to provide [the service]. We will give [30] days' notice of additions by [email / this page] to customers who have asked to be notified.

For each: Entity (country) | Purpose | Data categories | Hosting region | Transfer mechanism | Agreement | Date added

Or keep it somewhere that maintains it. Rowpa's vendor register holds 400 source-linked entries with the legal entity, DPA link, hosting country and transfer mechanism, re-checked monthly. Your sub-processor list is the vendors you have linked to processing activities, published on your Trust Center at its own address, with a form for customers who want an email when it changes, and included in every supplier pack, with the DPA status shown honestly for each. How the published list works. What else goes in the pack.

Your sub-processor list, from a website scan. Rowpa finds the tools you run, names the entity behind each, and checks the DPA. Free to build.

Scan your site